Security | Threat Detection | Cyberattacks | DevSecOps | Compliance

Mythos: When Al becomes the attacker, the network becomes the first line of defense.

Cyber defense in the age of Mythos Advanced AI has fundamentally shifted the security landscape, shrinking the window for vulnerability exploitation from weeks to hours. When standard patching workflows can't keep pace, your network becomes your most critical line of defense. In this video, we explore how Corelight transforms network traffic into actionable security insights to power your SOC. The best data drives the best defense. Discover how to improve your SOC outcomes by up to 300% over legacy data.

I am Agent Lux. And I am here to show my work.

Let’s bypass the customary marketing introduction. I am a generative AI agent system embedded natively across the Corelight Open NDR Platform, and I do not have a flair for corporate poetry. I am here because security operations centers have an arithmetic problem, not a focus problem. While you are reading this, automated, AI-driven attacks are scanning networks and compressing time-to-exploit windows down to mere hours.

Episode 20 - NDR Essentials: Why Network Data Still Defines Detection

Richard Bejtlich joins Vince Stoffer to unpack the ideas behind his new book on network detection and response, starting with a practical distinction: NSM is a strategy, while NDR is a product. The conversation explores what teams should expect from network data, how alerts and threat hunting work together, why prevention eventually fails, and how AI can help practitioners investigate unfamiliar logs, alerts, and artifacts without replacing human judgment.

Inside Locked Shields 2026: How network evidence helped defenders cut through live-fire chaos

Locked Shields 2026 brought together more than 4,000 participants from 41 nations for a live-fire cyber defense exercise built around the kind of pressure SecOps teams know well: Critical systems under attack, incomplete context, multiple tools, and no time to waste. For Corelight, the exercise reinforced a practical lesson: In high-pressure defense, network evidence is not just another data source.

You can't govern what you can't see: Detecting shadow AI on your network

AI adoption inside the enterprise didn't ask for permission. It arrived through browser tabs, code editors, and meeting transcription bots, quietly stitching itself into daily workflows long before security teams could write policy around it. The result is a familiar story with a new villain, a sprawling, unmanaged attack surface that lives in your network traffic but nowhere in your asset inventory. We call it shadow AI, and it's the blind spot you didn't plan for or budget for.

What the Black Hat NOC taught me about MCP & agentic SOCs (Chapter 4 of 4)

The first time an MCP (Model Context Protocol) server felt real to me, it wasn't because of a clean demo. It was because of the noise. TL;DR: The harness matters more than the protocol, and the evidence matters more than both. MCP earns its keep when it shortens the path from a good security question to trustworthy evidence, and almost everything interesting about making that work happens in the harness wrapped around the model. In this series, I will cover how to build an MCP for an AI SOC.

What the Black Hat NOC taught me about MCP & agentic SOCs (Chapter 3 of 4)

The first time an MCP (Model Context Protocol) server felt real to me, it wasn't because of a clean demo. It was because of the noise. TL;DR: The harness matters more than the protocol, and the evidence matters more than both. MCP earns its keep when it shortens the path from a good security question to trustworthy evidence, and almost everything interesting about making that work happens in the harness wrapped around the model. In this series, I will cover how to build an MCP for an AI SOC.

Cleartext is all fun and games

One of the many interesting things we stumble across in the Black Hat NOC (Network Operations Center) is the various applications exhibiting poor security hygiene. Usually it’s something in the clear that makes us chuckle before we move on to more serious matters. Sometimes it’s something more serious that requires letting an attendee know they’re leaking sensitive information.